{"_id":"@bun-win32/amsi","_rev":"4-5f256ac2332569407f0bed74243831d9","name":"@bun-win32/amsi","dist-tags":{"latest":"2.0.1"},"versions":{"1.0.0":{"name":"@bun-win32/amsi","version":"1.0.0","keywords":["bun","ffi","win32","windows","amsi","bindings","typescript","dll"],"author":"Stev Peifer <stev@bell.net>","license":"MIT","_id":"@bun-win32/amsi@1.0.0","maintainers":[{"name":"obscuritysrl","email":"stev@bell.net"}],"homepage":"https://github.com/ObscuritySRL/bun-win32#readme","bugs":{"url":"https://github.com/ObscuritySRL/bun-win32/issues"},"dist":{"shasum":"29f42a46f9071819547991e3be90dfb63d9fa8ef","tarball":"https://registry.npmjs.org/@bun-win32/amsi/-/amsi-1.0.0.tgz","fileCount":6,"integrity":"sha512-Wq/12mm/OABu4l2bSzFGTn5vuXbio8NCF7ebaMYSoP2FM/09j2BTwIgkoZiGygyqXJ1nO9P6wKQn3KnRs0y8jQ==","signatures":[{"sig":"MEYCIQCxMOcWVWmbDKnEuJbiuSJgL8eevcJ6pa3aDEz5QjfS1QIhAMjDdtXpscEf133TIVFYgM5heOZiPUdH/IXOl9lmPN7U","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":12044},"main":"./index.ts","type":"module","module":"index.ts","shasum":"29f42a46f9071819547991e3be90dfb63d9fa8ef","engines":{"bun":">=1.1.0"},"exports":{".":"./index.ts"},"private":false,"scripts":{"example:amsi-diagnostic":"bun ./example/amsi-diagnostic.ts","example:malware-scanner":"bun ./example/malware-scanner.ts"},"_npmUser":{"name":"obscuritysrl","email":"stev@bell.net"},"_integrity":"sha512-Wq/12mm/OABu4l2bSzFGTn5vuXbio8NCF7ebaMYSoP2FM/09j2BTwIgkoZiGygyqXJ1nO9P6wKQn3KnRs0y8jQ==","repository":{"url":"git://github.com/ObscuritySRL/bun-win32.git","type":"git","directory":"packages/amsi"},"_npmVersion":"10.8.3","description":"Zero-dependency, zero-overhead Win32 AMSI bindings for Bun (FFI) on Windows.","directories":{},"sideEffects":false,"_nodeVersion":"24.3.0","dependencies":{"@bun-win32/core":"1.1.2"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","@bun-win32/kernel32":"1.0.21"},"peerDependencies":{"typescript":"^5"},"_npmOperationalInternal":{"tmp":"tmp/amsi_1.0.0_1779150534345_0.9616932775484315","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@bun-win32/amsi","version":"1.0.1","keywords":["bun","ffi","win32","windows","amsi","bindings","typescript","dll"],"author":"Stev Peifer <stev.p@outlook.com>","license":"MIT","_id":"@bun-win32/amsi@1.0.1","maintainers":[{"name":"obscuritysrl","email":"stev@bell.net"}],"homepage":"https://github.com/ObscuritySRL/bun-win32#readme","bugs":{"url":"https://github.com/ObscuritySRL/bun-win32/issues"},"dist":{"shasum":"92032bd5cd2a8ca99512f20e15bb010af190737a","tarball":"https://registry.npmjs.org/@bun-win32/amsi/-/amsi-1.0.1.tgz","fileCount":6,"integrity":"sha512-hfMNqZNcqM+w8HGtNJGMVh/L44EyY8mEDe3u3GDnECfhKz533JGxQVm2Mk53n/j3cbS4xN9xMDHb9uIR+QEUHg==","signatures":[{"sig":"MEUCIDCtdrjzfIQhVWQTU7qxJ0lHDMAtcig+3j8yfJUoq/fHAiEAlAtAIgpRkPadtwXc+i5ulv+Rjjalsk+dQGhoCDPM8Es=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":12049},"main":"./index.ts","type":"module","module":"index.ts","shasum":"92032bd5cd2a8ca99512f20e15bb010af190737a","engines":{"bun":">=1.1.0"},"exports":{".":"./index.ts"},"private":false,"scripts":{"example:amsi-diagnostic":"bun ./example/amsi-diagnostic.ts","example:malware-scanner":"bun ./example/malware-scanner.ts"},"_npmUser":{"name":"obscuritysrl","email":"stev@bell.net"},"_integrity":"sha512-hfMNqZNcqM+w8HGtNJGMVh/L44EyY8mEDe3u3GDnECfhKz533JGxQVm2Mk53n/j3cbS4xN9xMDHb9uIR+QEUHg==","repository":{"url":"git://github.com/ObscuritySRL/bun-win32.git","type":"git","directory":"packages/amsi"},"_npmVersion":"10.8.3","description":"Zero-dependency, zero-overhead Win32 AMSI bindings for Bun (FFI) on Windows.","directories":{},"sideEffects":false,"_nodeVersion":"24.3.0","dependencies":{"@bun-win32/core":"1.1.4"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","@bun-win32/kernel32":"1.0.26"},"peerDependencies":{"typescript":"^5"},"_npmOperationalInternal":{"tmp":"tmp/amsi_1.0.1_1781130781027_0.986666811864596","host":"s3://npm-registry-packages-npm-production"}},"2.0.0":{"name":"@bun-win32/amsi","version":"2.0.0","keywords":["bun","ffi","win32","windows","amsi","bindings","typescript","dll"],"author":"Stev Peifer <stev.p@outlook.com>","license":"MIT","_id":"@bun-win32/amsi@2.0.0","maintainers":[{"name":"obscuritysrl","email":"stev.p@outlook.com"}],"homepage":"https://github.com/ObscuritySRL/bun-win32#readme","bugs":{"url":"https://github.com/ObscuritySRL/bun-win32/issues"},"dist":{"shasum":"bee40044fd6fcce9ccb2736c08089955bc4e6037","tarball":"https://registry.npmjs.org/@bun-win32/amsi/-/amsi-2.0.0.tgz","fileCount":6,"integrity":"sha512-jVLPB0x1BmZCDLALL/JIFB5U6YiCsEWXyPgzFyLAeH3QPsobbO2pWbEXsxqCZMBkJO15q6NiKFZNsilmFiEl2Q==","signatures":[{"sig":"MEUCIQCGWGM2S4wjNxsyIi8DFtfSv7ZJUc6rjclfWlhGOPQh5AIgf/FG7fK54ruV2biMOP2ZmNp5alS71nw8O6J2G1akWGo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":13363},"main":"./index.ts","type":"module","module":"index.ts","shasum":"bee40044fd6fcce9ccb2736c08089955bc4e6037","engines":{"bun":">=1.1.0"},"exports":{".":"./index.ts"},"private":false,"scripts":{"example:amsi-diagnostic":"bun ./example/amsi-diagnostic.ts","example:malware-scanner":"bun ./example/malware-scanner.ts"},"_npmUser":{"name":"obscuritysrl","email":"stev.p@outlook.com"},"_integrity":"sha512-jVLPB0x1BmZCDLALL/JIFB5U6YiCsEWXyPgzFyLAeH3QPsobbO2pWbEXsxqCZMBkJO15q6NiKFZNsilmFiEl2Q==","repository":{"url":"git://github.com/ObscuritySRL/bun-win32.git","type":"git","directory":"packages/amsi"},"_npmVersion":"10.8.3","description":"Zero-dependency, zero-overhead Win32 AMSI bindings for Bun (FFI) on Windows.","directories":{},"sideEffects":false,"_nodeVersion":"26.3.0","dependencies":{"@bun-win32/core":"2.0.0"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","@bun-win32/kernel32":"2.0.0"},"peerDependencies":{"typescript":"^5"},"_npmOperationalInternal":{"tmp":"tmp/amsi_2.0.0_1782435265805_0.2853407077941206","host":"s3://npm-registry-packages-npm-production"}},"2.0.1":{"author":"Stev Peifer <stev.p@outlook.com>","bugs":{"url":"https://github.com/ObscuritySRL/bun-win32/issues"},"dependencies":{"@bun-win32/core":"2.0.1"},"description":"Zero-dependency, zero-overhead Win32 AMSI bindings for Bun (FFI) on Windows.","devDependencies":{"@bun-win32/kernel32":"2.0.1","@types/bun":"latest"},"exports":{".":"./index.ts"},"license":"MIT","module":"index.ts","name":"@bun-win32/amsi","peerDependencies":{"typescript":"^5"},"private":false,"homepage":"https://github.com/ObscuritySRL/bun-win32#readme","repository":{"type":"git","url":"git://github.com/ObscuritySRL/bun-win32.git","directory":"packages/amsi"},"type":"module","version":"2.0.1","main":"./index.ts","keywords":["bun","ffi","win32","windows","amsi","bindings","typescript","dll"],"sideEffects":false,"engines":{"bun":">=1.1.0"},"scripts":{"example:malware-scanner":"bun ./example/malware-scanner.ts","example:amsi-diagnostic":"bun ./example/amsi-diagnostic.ts"},"_id":"@bun-win32/amsi@2.0.1","_integrity":"sha512-0V3A74yRqbtteJSLJA6nFVBSpoAaaGYJ5PqQSOYthaoKIGrxS/bOqIqscQ8kWtmD2vUKT4LJAWCP8QD3VluG5w==","_nodeVersion":"26.3.0","_npmVersion":"10.8.3","shasum":"b9200f436c95be4054a0b023aa8e5ff26bdc08f4","dist":{"integrity":"sha512-0V3A74yRqbtteJSLJA6nFVBSpoAaaGYJ5PqQSOYthaoKIGrxS/bOqIqscQ8kWtmD2vUKT4LJAWCP8QD3VluG5w==","shasum":"b9200f436c95be4054a0b023aa8e5ff26bdc08f4","tarball":"https://registry.npmjs.org/@bun-win32/amsi/-/amsi-2.0.1.tgz","fileCount":6,"unpackedSize":13363,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDnZevz03S7RMo341kbJfSMrQSOppcb6NJeU8ptr+/f8AIhANgaUhkSGZa2dTDhkVfhJYBg49gi1ukwZkuMnDAfH27J"}]},"_npmUser":{"name":"obscuritysrl","email":"stev.p@outlook.com"},"directories":{},"maintainers":[{"name":"obscuritysrl","email":"stev.p@outlook.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/amsi_2.0.1_1782437719937_0.3679115068996328"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-19T00:28:54.230Z","modified":"2026-06-26T01:35:20.199Z","1.0.0":"2026-05-19T00:28:54.501Z","1.0.1":"2026-06-10T22:33:01.218Z","2.0.0":"2026-06-26T00:54:25.967Z","2.0.1":"2026-06-26T01:35:20.068Z"},"bugs":{"url":"https://github.com/ObscuritySRL/bun-win32/issues"},"author":"Stev Peifer <stev.p@outlook.com>","license":"MIT","homepage":"https://github.com/ObscuritySRL/bun-win32#readme","keywords":["bun","ffi","win32","windows","amsi","bindings","typescript","dll"],"repository":{"type":"git","url":"git://github.com/ObscuritySRL/bun-win32.git","directory":"packages/amsi"},"description":"Zero-dependency, zero-overhead Win32 AMSI bindings for Bun (FFI) on Windows.","maintainers":[{"name":"obscuritysrl","email":"stev.p@outlook.com"}],"readme":"# @bun-win32/amsi\n\nZero-dependency, zero-overhead Win32 AMSI bindings for [Bun](https://bun.sh) on Windows.\n\n## Overview\n\n`@bun-win32/amsi` exposes the `amsi.dll` exports using [Bun](https://bun.sh)'s FFI. It provides a single class, `Amsi`, which lazily binds native symbols on first use. You can optionally preload a subset or all symbols up-front via `Preload()`.\n\nThe Antimalware Scan Interface (AMSI) lets an application submit arbitrary content — scripts, buffers, downloaded payloads — to the registered antivirus provider (Windows Defender by default) for in-process scanning, with no temp files and no shelling out. It is the same pipeline PowerShell, WScript, and Office use.\n\nThe bindings are strongly typed for a smooth DX in TypeScript.\n\n## Features\n\n- [Bun](https://bun.sh)-first ergonomics on Windows 10/11.\n- Direct FFI to `amsi.dll` (in-process malware scanning via the registered AV provider).\n- In-source docs in `structs/Amsi.ts` with links to Microsoft Docs.\n- Lazy binding on first call; optional eager preload (`Amsi.Preload()`).\n- No wrapper overhead; calls map 1:1 to native APIs.\n- Strongly-typed Win32 aliases (see `types/Amsi.ts`).\n\n## Requirements\n\n- [Bun](https://bun.sh) runtime\n- Windows 10 or later\n\n## Installation\n\n```sh\nbun add @bun-win32/amsi\n```\n\n## Quick Start\n\n```ts\nimport Amsi, { AMSI_RESULT } from '@bun-win32/amsi';\n\nconst ctxBuf = Buffer.alloc(8);\nif (Amsi.AmsiInitialize(Buffer.from('MyApp\\0', 'utf16le').ptr, ctxBuf.ptr) === 0) {\n  const ctx = ctxBuf.readBigUInt64LE(0);\n\n  const result = Buffer.alloc(4);\n  const content = Buffer.from('console.log(\"hello\")\\0', 'utf16le');\n  Amsi.AmsiScanString(ctx, content.ptr, Buffer.from('snippet\\0', 'utf16le').ptr, 0n, result.ptr);\n\n  const code = result.readInt32LE(0);\n  const isMalware = code >= AMSI_RESULT.AMSI_RESULT_DETECTED;\n  console.log(isMalware ? 'BLOCK' : 'allow', `(AMSI_RESULT=${code})`);\n\n  Amsi.AmsiUninitialize(ctx); // always pair with AmsiInitialize\n}\n```\n\n> [!NOTE]\n> AI agents: see `AI.md` for the package binding contract and source-navigation guidance. It explains how to use the package without scanning the entire implementation.\n\n## Examples\n\nRun the included examples:\n\n```sh\nbun run example/malware-scanner.ts\nbun run example/amsi-diagnostic.ts\n```\n\n## Notes\n\n- Either rely on lazy binding or call `Amsi.Preload()`.\n- Always pair `AmsiInitialize` with `AmsiUninitialize`, and `AmsiOpenSession` with `AmsiCloseSession`.\n- `result` is an out-pointer to an `AMSI_RESULT` (`Int32`): use `AmsiResultIsMalware` semantics — `code >= AMSI_RESULT_DETECTED` (32768) means block.\n- Windows only. Bun runtime required.\n- **SAL types & naming:** nullability is in the **type** — `Optional<T>` (formally optional, SAL `_*opt_`) and `Nullable<T>` (plain `[in]`/`[out]` the docs say can be NULL), the null sentinel derived from `T` (`null` for pointers `LP*`/`P*`, `0n` for handles/by-value addresses); direction is in the **parameter name** — `_out` (`_Out_`), `_in_out` (`_Inout_`), `_In_` bare. See `AI.md` and the repo `AGENTS.md`.\n","readmeFilename":"README.md"}